Bug 33753 - How to modify GPO ACL's (security filter in the GPMC) in an ucs@school scenario without samba4 on the UCS master?
How to modify GPO ACL's (security filter in the GPMC) in an ucs@school scenar...
Status: RESOLVED DUPLICATE of bug 33751
Product: UCS@school
Classification: Unclassified
Component: Samba 4
unspecified
Other Linux
: P5 normal (vote)
: ---
Assigned To: Samba maintainers
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2013-12-16 10:35 CET by Felix Botner
Modified: 2013-12-16 14:12 CET (History)
1 user (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Felix Botner univentionstaff 2013-12-16 10:35:25 CET
UCS@School env with UCS master and school slave, NO samba4 on the master
and a window client (joined into the slave's samba4 domain)

Now i want to change the security filter for a gpo via the GPMC. I added a user 

-> getfacl sysvol/fff.ggg/Policies/\{8B4EB339-A049-4C4B-BC35-DB7BF13D2D5E\}/GPT.INI
...
user:sch1:r-x
...

After five minutes my changes are overwritten. 

The problem is that in an ucs@school env the sysvol/sync parent is always the ucs master and the slaves resync the master's sysvol directory to the local sysvol and overwrite the locally changed ACL's with the unmodified ACL's from the master.

So, how do i change GPO ACL's in this scenario (without samba4 on the master)?
Comment 1 Arvid Requate univentionstaff 2013-12-16 14:12:21 CET
sysvol-sync is bidirectional, so I can't see the difference to Bug 33751.

*** This bug has been marked as a duplicate of bug 33751 ***